1. Start with four separate control questions
Review KSeF access as four controls: identity, authentication, current permission and software capability. A certificate may authenticate successfully while the permissions register blocks an operation; a permitted user may still fail because the ERP cannot handle the credential securely. Map real workloads such as batch submission, Taxpayer Application use, accountant access and offline issuing. • Record the legal entity, environment, identity, method, owner and expected operations. • Scope shared services and vendors separately for every NIP. • Report certificate validity, permissions and tested software readiness as distinct statuses. • Check current Ministry material and refer legal or tax interpretation to an appropriate adviser.